CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. |
The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data. |
3Canonical GnuOpensuse4Leap LibidnOpensuse+1 moreMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948. |
3Canonical GnuOpensuse3Leap LibidnUbuntu LinuxMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input. |
3Canonical GnuOpensuse4Leap LibidnOpensuse+1 moreMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read. |
3Fedoraproject GnuOpensuse3Fedora LibidnOpensuseMay 6, 2026 Aug 12, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string...Show more |